Sap Se Sap Hana vulnerabilities
6 known vulnerabilities affecting sap_se/sap_hana.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2021-21484CRITICALCVSS 9.8fixed in 2.02021-03-09
CVE-2021-21484 [CRITICAL] CWE-863 CVE-2021-21484: LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind.
cvelistv5nvd
CVE-2019-0357MEDIUMCVSS 6.7fixed in 1.0fixed in 2.02019-09-10
CVE-2019-0357 [MEDIUM] CVE-2019-0357: The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute comm
The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating system "root" privileges.
cvelistv5nvd
CVE-2019-0284MEDIUMCVSS 6.0fixed in 1.0fixed in 2.02019-04-10
CVE-2019-0284 [MEDIUM] CWE-611 CVE-2019-0284: SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML docu
SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for example, continuously loop, read arbitrary files and even send local files.
cvelistv5nvd
CVE-2018-2402HIGHCVSS 8.4v1.0v2.02018-03-14
CVE-2018-2402 [HIGH] CWE-200 CVE-2018-2402: In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP No
In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user c
cvelistv5nvd
CVE-2018-2369MEDIUMCVSS 5.3v1.00v2.002018-02-14
CVE-2018-2369 [MEDIUM] CVE-2018-2369: Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access informat
Under certain conditions SAP HANA, 1.00, 2.00, allows an unauthenticated attacker to access information which would otherwise be restricted. An attacker can misuse the authentication function of the SAP HANA server on its SQL interface and disclose 8 bytes of the server process memory. The attacker cannot influence or predict the location of the leaked memory
cvelistv5nvd
CVE-2018-2362MEDIUMCVSS 5.3v1.00v2.002018-01-09
CVE-2018-2362 [MEDIUM] CVE-2018-2362: A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP request
A remote unauthenticated attacker, SAP HANA 1.00 and 2.00, could send specially crafted SOAP requests to the SAP Startup Service and disclose information such as the platform's hostname.
cvelistv5nvd